Sato Hub
← Sato Check

Sato Check · Package

brickken-cli

npm:brickken-cli · v0.4.13 · sha256:87bfdcf99486 · as of 2026-09-29

Does it take your key?
traced
Yes — it reads private-key material. Local signing is what a wallet does; question 2 says whether the key leaves.
Our static read of the published artifact found it.
Does your key leave?
no evidence
Not yet run — we have not run this version with planted test keys.
No evidence line on file for this question yet.
Can it move funds on its own?
no evidence
Unknown — we could not read what it exposes.
No evidence line on file for this question yet.
What changed?
no evidence
First profile of this subject — nothing to compare yet.
No evidence line on file for this question yet.

Is this your project? Respond →Dispute this reading

Hosts contacted

HostWhenRoleEvidence
api.brickken.comcodevendortraced
api.sandbox.brickken.comcodevendortraced
d4aqanatl1.execute-api.eu-west-1.amazonaws.comcodeothertraced
ethereum-sepolia-rpc.publicnode.comcoderpctraced
Evidence (12 lines)
  • tracedT-key-read2026-09-29

    Reads process.env.BRICKKEN_PRIVATE_KEY.

    dist/cli-config.js:48

  • tracedT-key-read2026-09-29

    Reads process.env.BKN_PRIVATE_KEY.

    dist/cli-config.js:48

  • tracedT-key-read2026-09-29

    Reads process.env.BRICKKEN_PRIVATE_KEY.

    dist/internal/core/config.js:59

  • tracedT-key-read2026-09-29

    Reads process.env.BKN_PRIVATE_KEY.

    dist/internal/core/config.js:59

  • tracedT-hosts2026-09-29

    api.brickken.com appears in shipped code (vendor).

    dist/internal/core/config.js

  • tracedT-hosts2026-09-29

    api.sandbox.brickken.com appears in shipped code (vendor).

    dist/internal/core/config.js

  • tracedT-hosts2026-09-29

    d4aqanatl1.execute-api.eu-west-1.amazonaws.com appears in shipped code (other).

    dist/internal/core/config.js

  • tracedT-hosts2026-09-29

    ethereum-sepolia-rpc.publicnode.com appears in shipped code (rpc).

    dist/internal/core/receipts.js

  • tracedT-key-named2026-09-29

    The shipped code names BRICKKEN_PRIVATE_KEY in a message to the user.

    dist/commands/rams.js

  • tracedT-key-named2026-09-29

    The shipped code names BKN_PRIVATE_KEY in a message to the user.

    dist/commands/rams.js

  • declaredD-env-key2026-09-29

    Setup names BRICKKEN_PRIVATE_KEY as something to provide.

    deploy_spec.requires

  • declaredD-env-key2026-09-29

    Setup names BKN_PRIVATE_KEY as something to provide.

    brickken-cli@0.4.13/README.md

Limits

  • The observed lane has not run on this version: not yet run on this version
  • Traced analysis follows flows inside one module only; a key handed from one module to another is not followed.
  • The observed lane has not run on this version.
  • No tool inventory was available, so fund actions were not read.

A profile describes what we read and ran, with dates. It is not a safety rating, an audit or an endorsement, and "not found" is not "not there".

sato.custody/v1 · custody-1

Maintain this project? Respond to this reading

Loading sign-in…